SSD Nodes Learn
How to do am Matt ConnorBy Matt Connor · Updated 2026-07-24

how to set up UFW firewall for VPS

Learn how to use UFW for your VPS. We go show you how to set default-deny policy and how to allow SSH so you no go lock yourself out of your server.

Wetin UFW be and why you need am

UFW stand for Uncomplicated Firewall, and de name true. Na friendly front end for de firewall wey Linux kernel already get. Instead of to dey write raw rules, you go dey type short commands like ufw allow 22/tcp. For brand new VPS, every service wey dey listen for port dey open to de internet by default. Firewall dey change dat thing: you go deny everything, den you go allow only de few ports wey you really need. Dat single change go reduce your risk plenty for just four commands.

Before you touch am, make sure you know wetin dey listen, because na dem de firewall dey decide wetin go happen to dem. Read wetin dey listen with ss -tlnp na de right first step.

One rule wey go prevent you from locking yourself out

Dis mistake na wetin dey scare many people from using firewalls. You fit enable UFW with default-deny policy, but if you no allow SSH, as soon as firewall start, your own connection go cut and you no go fit enter again. To avoid dis, always allow SSH before you enable UFW. Na dat one be di trick, and di steps below go show you how to do am for safe order.

If dis thing happen to you, no fear: your provider web console, via VNC or serial, no dey use SSH, so you fit log in there and run ufw disable or add di rule wey dey missing.

Step 1: Set the default policies

First, tell UFW say make e deny everything wey dey come in and allow everything wey dey go out:

sudo ufw default deny incoming
sudo ufw default allow outgoing

deny incoming na the important part. E mean say any port wey no get special allow rule, e closed to the outside, even if service dey listen for am. allow outgoing make your server fit reach internet normally for updates and other things. These two commands na only to change policy; nothing go happen until you enable UFW for step 3.

Step 2: Allow the ports wey you really need

Before you enable am, open SSH so your connection no go cut:

sudo ufw allow 22/tcp

UFW fit also rate-limit SSH for you: sudo ufw limit 22/tcp allow the port but block any address wey try make six or more connections inside thirty seconds. This one dey stop brute-force scripts without extra software.

If you dey run web server, allow HTTP and HTTPS too:

sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

Allow only wetin you wan serve to public. Database like Postgres for port 5432 no suppose get allow rule almost always. Bind am to 127.0.0.1 instead so only the machine fit reach am. Every port wey you open na door wey you must defend, so keep the list short.

You fit also build the full sequence of ufw commands for your server for here, then run dem one by one:

ToolUFW rule generator

Step 3: Enable, and confirm it is on

sudo ufw enable

E dey warn say the command fit cut existing SSH connections. Because you don allow 22/tcp for step 2, your session no go fall. Confirm the result:

sudo ufw status verbose
Status: active
Default: deny (incoming), allow (outgoing)

To                         Action      From
--                         ------      ----
22/tcp                     ALLOW IN    Anywhere
22/tcp (v6)                ALLOW IN    Anywhere (v6)
80/tcp                     ALLOW IN    Anywhere

Look two things for here. Status: active mean say firewall dey run. And every rule go show twice, once for plain and once with (v6), wey mean say UFW dey cover IPv6 as well as IPv4. If you no see (v6) lines, your IPv6 side no dey manage, and that one na trap wey dem explain for the IPv6 firewall post.

Managing rules later

To see rules with numbers so you fit remove one:

sudo ufw status numbered
sudo ufw delete 3

To allow one port for only one address, which na beta way to expose admin service to only your own IP:

sudo ufw allow from 10.0.0.24 to any port 5432 proto tcp

Firewall na just one layer. E dey control wetin fit reach one port, but e no dey slow down person wey dey hammer one port wey you leave open, like SSH. For that one, add Fail2ban for front of SSH to ban people wey dey repeat mistake. Defence in depth means say each layer dey cover wetin the others no fit cover.

Firewall only make sense once you know wetin ports be and how services dey listen, and to configure one na part of the first 10 minutes for new VPS.

FAQ

If I enable UFW, my SSH session go disconnect?

E no go disconnect if you allow SSH first. Run sudo ufw allow 22/tcp before sudo ufw enable, and your connection go still dey because firewall don permit port 22. The wahala na to enable default-deny firewall without SSH allow rule, because dat one go cut you off. If dat happen, log in through your provider VNC or serial console and run ufw disable.

Which ports I suppose open for VPS?

Only di ones wey you dey serve to public. SSH (22/tcp) so you fit manage di box, and HTTP and HTTPS (80/tcp, 443/tcp) if you dey run website. Leave everything else as deny. Internal services like databases suppose bind to 127.0.0.1 and dem no need firewall rule at all, so nobody fit reach dem from di network.

UFW dey handle IPv6?

For modern Ubuntu, e dey handle am: IPV6=yes dey inside /etc/default/ufw, so every rule go work for both stacks and ufw status go show di IPv6 rules with (v6) suffix. Di ways wey e fit still fail dey di IPv6 firewall trap.

How I go take remove UFW rule?

Run sudo ufw status numbered to see di rules with index numbers, then run sudo ufw delete N where N na di number of di rule wey you want remove. You fit also delete by specification, for example sudo ufw delete allow 80/tcp.

How I go allow port for only one IP address?

Use from rule instead of plain allow. To make only your office address reach PostgreSQL, run sudo ufw allow from 10.0.0.10 to any port 5432 proto tcp. Since default-deny policy dey, di port dey closed to everybody until rule open am, so dis from rule na di only way in: di whole internet go remain blocked and only di address wey you name go pass. No add plain allow 5432/tcp, because dat one go open di port to everybody. Dis na di safest way to expose database or admin panel. Confirm am with sudo ufw status verbose, wey go show di source address beside di port.